self-learning

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose broadly matches its capabilities, but its core design is risky: it converts untrusted web content into persistent agent instructions and saves them as installable skills. That creates a high prompt-injection and transitive-trust risk even without obvious credential theft or malicious exfiltration.

Confidence: 91%Severity: 76%
Audit Metadata
Analyzed At
Jul 24, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/jeremielim%2Fskills%2Fself-learning%2F@f976a891b1bfcf969a11da4b5ac7ecd2c6d8d9e4139f43b78b34e7f1a6140f4b
Security Audit — socket — self-learning